Server-Side Request Forgery Vulnerability in MISP by MISP Project
CVE-2022-27245
8.8HIGH
What is CVE-2022-27245?
A security issue has been identified in MISP prior to version 2.4.156, where the generateServerSettings function within the app/Model/Server.php file does not adequately restrict access to command line interface (CLI) execution. This oversight may enable an attacker to exploit the application by manipulating server requests, potentially leading to unauthorized access and data exposure.
